VORANT. Threat Intelligence Sign in Get the full feed

Microsoft patches actively exploited CVE-2026-20805

high vulnerability

Microsoft's January 2026 Patch Tuesday addresses multiple vulnerabilities including CVE-2026-20805, which is actively exploited in the wild.

Japan's IPA (Information-technology Promotion Agency) has issued an advisory regarding Microsoft's January 2026 security update release. The update addresses multiple vulnerabilities that could lead to application crashes or allow attackers to gain control of affected systems.

Microsoft has confirmed active exploitation of CVE-2026-20805, indicating threat actors are already leveraging this vulnerability in real-world attacks. IPA is urging organizations to apply security updates immediately to prevent further compromise. The advisory emphasizes that the threat is escalating and immediate action is required.

The updates are typically deployed automatically through Windows Update for most users. Organizations managing their own update processes should consult Microsoft's official patch documentation and expedite deployment across their environments. Systems may require a restart to complete the security update installation.

Mentioned in this report

Vulnerabilities CVE-2026-20805KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/0114-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free